CVE-2019-16777
published 2019-12-13CVE-2019-16777: Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCNIHAN
EPSS
1.98%
78.2th percentile
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | npm | < npm 6.13.4+ds-2 (bookworm) | npm 6.13.4+ds-2 (bookworm) |
| fedoraproject | fedora | — | — |
| npm | cli | < 6.13.4 | 6.13.4 |
| npmjs | npm | < 6.13.4 | 6.13.4 |
| npmjs | npm | >= 0 < 6.13.4+ds-2 | 6.13.4+ds-2 |
| npmjs | npm | >= 0 < 6.13.4+ds-2 | 6.13.4+ds-2 |
| npmjs | npm | >= 0 < 6.13.4+ds-2 | 6.13.4+ds-2 |
| npmjs | npm | >= 0 < 6.13.4+ds-2 | 6.13.4+ds-2 |
| npmjs | npm | >= 0 < 6.13.4 | 6.13.4 |
| opensuse | leap | — | — |
| oracle | graalvm | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
osv6.5MEDIUM
vendor_debian7.7HIGH
vendor_redhat7.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
npm: Global node_modules Binary Overwrite
vendor_redhat·2019-12-12·CVSS 7.7
CVE-2019-16777 [HIGH] CWE-20 npm: Global node_modules Binary Overwrite
npm: Global node_modules Binary Overwrite
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Package: nodejs8 (Red Hat OpenShift Application Runtimes) - Out of support scope
Debian
CVE-2019-16777: npm - Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Over...
vendor_debian·2019·CVSS 7.7
CVE-2019-16777 [HIGH] CVE-2019-16777: npm - Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Over...
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
Scope: local
bookworm: resolved (fixed in 6.13.4+ds-2)
bullseye: resolved (fixed in 6.13.4+ds-2)
forky: resolved (fixed in 6.13.4+ds-2)
sid: resolved (fixed in 6.13.4+ds-2)
trixie: resolved (fixed in 6.13.4+ds-2)
GHSA
npm Vulnerable to Global node_modules Binary Overwrite
ghsa·2019-12-13
CVE-2019-16777 [HIGH] CWE-22 npm Vulnerable to Global node_modules Binary Overwrite
npm Vulnerable to Global node_modules Binary Overwrite
Versions of the npm CLI prior to 6.13.4 are vulnerable to a Global node_modules Binary Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations.
For example, if a package was installed globally and created a `serve` binary, any subsequent installs of packages that also create a `serve` binary would overwrite the first binary. This will not overwrite system binaries but only binaries put into the global node_modules directory.
This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
## Recommendation
Upgrade to version 6.13.4 or later.
OSV
CVE-2019-16777: Versions of the npm CLI prior to 6
osv·2019-12-13·CVSS 6.5
CVE-2019-16777 [MEDIUM] CVE-2019-16777: Versions of the npm CLI prior to 6
Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package was installed globally and created a serve binary, any subsequent installs of packages that also create a serve binary would overwrite the previous serve binary. This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
OSV
npm Vulnerable to Global node_modules Binary Overwrite
osv·2019-12-13
CVE-2019-16777 [HIGH] npm Vulnerable to Global node_modules Binary Overwrite
npm Vulnerable to Global node_modules Binary Overwrite
Versions of the npm CLI prior to 6.13.4 are vulnerable to a Global node_modules Binary Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations.
For example, if a package was installed globally and created a `serve` binary, any subsequent installs of packages that also create a `serve` binary would overwrite the first binary. This will not overwrite system binaries but only binaries put into the global node_modules directory.
This behavior is still allowed in local installations and also through install scripts. This vulnerability bypasses a user using the --ignore-scripts install option.
## Recommendation
Upgrade to version 6.13.4 or later.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-16777 nodejs: Global node_modules Binary Overwrite via npm CLI [fedora-all]
bugzilla·2020-01-06·CVSS 7.7
CVE-2019-16777 [HIGH] CVE-2019-16777 nodejs: Global node_modules Binary Overwrite via npm CLI [fedora-all]
CVE-2019-16777 nodejs: Global node_modules Binary Overwrite via npm CLI [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported v
Bugzilla
CVE-2019-16777 npm: Global node_modules Binary Overwrite
bugzilla·2020-01-06·CVSS 7.8
CVE-2019-16777 [HIGH] CVE-2019-16777 npm: Global node_modules Binary Overwrite
CVE-2019-16777 npm: Global node_modules Binary Overwrite
Versions of the npm CLI prior to 6.13.4 are vulnerable to a Global node_modules Binary Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations.
References:
https://www.npmjs.com/advisories/1437
https://nodejs.org/en/blog/vulnerability/december-2019-security-releases/
https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-cli
Discussion:
Created nodejs tracking bugs for this issue:
Affects: epel-all [bug 1788303]
Affects: fedora-all [bug 1788302]
---
Red Hat Quay versions up to v3.2.0 are affected by the use of yarn to install client side dependencies. Red Hat Quay uses the npm package from RHEL 7 so that will be updated once a fix for RHEL 7 is availa
Bugzilla
CVE-2019-16777 nodejs: npm: Global node_modules Binary Overwrite [epel-all]
bugzilla·2020-01-06·CVSS 7.7
CVE-2019-16777 [HIGH] CVE-2019-16777 nodejs: npm: Global node_modules Binary Overwrite [epel-all]
CVE-2019-16777 nodejs: npm: Global node_modules Binary Overwrite [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00027.htmlhttps://access.redhat.com/errata/RHEA-2020:0330https://access.redhat.com/errata/RHSA-2020:0573https://access.redhat.com/errata/RHSA-2020:0579https://access.redhat.com/errata/RHSA-2020:0597https://access.redhat.com/errata/RHSA-2020:0602https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-clihttps://github.com/npm/cli/security/advisories/GHSA-4328-8hgf-7wjrhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z36UKPO5F3PQ3Q2POMF5LEKXWAH5RUFP/https://security.gentoo.org/glsa/202003-48https://www.oracle.com/security-alerts/cpujan2020.htmlhttp://lists.opensuse.org/opensuse-security-announce/2020-01/msg00027.htmlhttps://access.redhat.com/errata/RHEA-2020:0330https://access.redhat.com/errata/RHSA-2020:0573https://access.redhat.com/errata/RHSA-2020:0579https://access.redhat.com/errata/RHSA-2020:0597https://access.redhat.com/errata/RHSA-2020:0602https://blog.npmjs.org/post/189618601100/binary-planting-with-the-npm-clihttps://github.com/npm/cli/security/advisories/GHSA-4328-8hgf-7wjrhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/Z36UKPO5F3PQ3Q2POMF5LEKXWAH5RUFP/https://security.gentoo.org/glsa/202003-48https://www.oracle.com/security-alerts/cpujan2020.html
2019-12-13
Published